SOURCE-LINKED INTELLIGENCE
GHSA-h6m6-jj8v-94jj: SQL injection in litellm
An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability arises due to improper neutralization of special elements used in an SQL command. The affected code constructs an SQL query by concatenating an unvalidated `api_key` parameter directly into the query, making it susceptible to SQL Injection if the `api_key` contains malicious data. This issue affects the latest version of the repository. Successful exploitation of this vulnerability could lead to unauthorized access, data manipulation, exposure of con
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-06-06T21:30:37.000Z
- OSV AI package advisories · 2026-07-07T14:34:34.436Z
First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.